Audit of Financial Guarantees
Executive Summary
The audit objective was to assess whether the financial guarantees in place, particularly where there is an assessed increased risk of exposure Footnote 1, comply with the criteria specified in the regulatory guidance and are supported by effective oversight and control processes.
Why is this important
Financial guarantees are a critical regulatory mechanism used by the Canadian Nuclear Safety Commission (CNSC) Footnote 2 to ensure that sufficient financial resources are available to safely decommission nuclear facilities and terminate licensed activities when required. Under the Nuclear Safety and Control Act (NSCA), the Commission has the authority to impose financial guarantees on licensees to protect the public interest and mitigate the risk that decommissioning obligations are not met due to licensee financial incapacity.
Financial guarantees rely on credible decommissioning cost estimates and on instruments that meet the CNSC’s acceptance criteria of liquidity, certainty of value, adequacy, and continuity, as set out in REGDOC-3.3.1. The effectiveness of this framework depends not only on the strength of the regulatory requirements and guidance, but also on the consistency, clarity and effectiveness of the CNSC’s internal processes for assessing and monitoring financial guarantees over the licensing lifecycle.
Since the 2018 audit of financial guarantees, the risk environment has evolved, including changes in licensee profiles, facility lifecycles, financial instruments, and past experiences where the financial guarantees were insufficient. The current regulatory document was published in January 2021 and included public and industry consultation. For these reasons, it is important to assess whether financial guarantees continue to provide sufficient assurance, particularly in higher-risk cases, and whether internal controls and oversight mechanisms remain fit for purpose. This audit sought to assess the management and oversight of financial guarantee requirements and whether risks of financial exposure to the CNSC are properly identified and mitigated. (see Appendix C 2018 vs. 2026 Audit Findings and Recommendations)
Key Findings
The CNSC has established a regulatory framework and supporting processes in place for management and oversight of the licensees’ financial guarantees and has been taking steps to update processes and information management with SharePoint. Recent enhancements, including updates to technical work instructions, development of improved tracking tools, and initiating updates to decommissioning costs for the insurance-based Financial Guarantee Program, demonstrate a commitment to improving consistency and transparency in the financial guarantee process.
The audit identified opportunities to strengthen governance, clarity of accountability, and the consistent application of risk informed oversight.
- Roles, responsibilities, and accountabilities across involved branches are documented but not always clearly understood, particularly with respect to end-to-end process ownership and accountability.
- Guidance and training are not yet consistently embedded across all functions, leading to variability in how financial guarantees and supporting cost estimates are reviewed and monitored.
- Some risks could be mitigated with updates to the regulatory document.
- Risk based considerations are not fully integrated into operational work instructions or consistently documented in practice. Controls and monitoring mechanisms, including periodic reviews and use of tracking systems, are not always applied as intended, increasing the risk that changes in licensee activities or risks may not be identified in a timely manner.
- The insurance based Financial Guarantee Program presents a growing coverage gap with decommissioning costs in select instances, highlighting the need for enhanced monitoring and responses where gaps are identified.
This audit includes 6 recommendations to address the above-noted areas for improvement, and the management agrees with the recommendations (see Appendix A).
Background
A financial guarantee is a tangible commitment by a licensee that there will be sufficient resources to safely terminate licensed activities. Failure to properly terminate licensed activities can result in risk to the health and safety of persons and the environment. A financial guarantee ensures there are funds available when licensees are unable to carry out safe termination of CNSC-licensed activities.
Pursuant to the Nuclear Safety and Control Act (NSCA), the Commission has the authority to require a financial guarantee in respect of facilities and activities that it regulates. Since the NSCA came into effect in 2000, the Commission has required financial guarantees for nuclear facilities or activities for Class IA and IB licences issued in accordance with the Class I Nuclear Facilities Regulations, uranium mines and mills licences and waste nuclear substances licences. In 2015, the Commission made a decision that amended licences for nuclear substances, prescribed equipment and Class II nuclear facilities to include requirements for financial guarantees. This was in accordance with a new insurance based financial instrument developed by the CNSC to ensure there are funds available when licensees are unable to carry out safe termination.
According to subsection 24(5) of the NSCA, “A licence may contain any term or condition that the Commission considers necessary for the purposes of this Act, including a condition that the applicant provide a financial guarantee in a form that is acceptable to the Commission”.
Class I and Class II nuclear facilities, uranium mines and mills, and nuclear substances and radiation devices licensees must develop and submit to the CNSC an acceptable plan for decommissioning, including credible estimates of the costs of implementing the licensee’s decommissioning activities and financial guarantees to fund these activities. The CNSC’s role is to perform a technical assessment to ensure the licensee’s proposed financial guarantee provides assurance that adequate resources will be available to fund the licensees’ decommissioning activities. The acceptance criteria for the financial guarantees for nuclear facilities or activities for Class IA and IB licences are detailed in the CNSC Regulatory document REGDOC-3.3.1, Financial Guarantees for Decommissioning of Nuclear Facilities and Termination of Licensed Activities, which include liquidity, certainty of value, adequacy of value and continuity. CNSC staff are responsible for assessing these criteria and making recommendations to the Commission. The Commission will then decide if a financial guarantee is acceptable, or, where a designated officer has issued a licence, the designated officer will decide.
Authority
The Audit of financial guarantees is under CNSC authority and was requested by the Executive Vice-President and Chief Regulatory Officer. This engagement is included in the 2025-2027 Risk Based Audit and Evaluation Plan.
Objective, scope and approach
The objective of this audit was to assess whether the financial guarantees in place, particularly where there is an assessed increased risk of exposure, comply with the criteria specified in the regulatory requirements and guidance. In addition, to provide insights to management on risks and controls regarding oversight of the financial guarantee requirements, including the assessment of preliminary decommissioning plans and cost estimates.
The audit methodology included a review of relevant documentation, interviews with stakeholders, and sample testing and confirmation of financial guarantee instruments based on the population as of April 1, 2025. Additionally, a comparative analysis was conducted with other organizations that administer similar financial guarantee programs. The audit analyzed six organizations, including international nuclear regulators and federal and provincial energy regulators.
The audit lines of inquiry and criteria are set out in detail in Appendix B.
Statement of Conformance
This audit conforms with the Institute of Internal Auditors' Global Internal Audit Standards, the Treasury Board Policy on Internal Audit and Directive on Internal Audit.
Findings and Observations
Roles, Responsabilities and Accountabillities
The audit expected that staff responsibilities and accountabilities in relation to financial guarantees are clearly defined, communicated, understood, and implemented.
Key Findings
The financial guarantee Work Instruction (for the technical assessment) was updated in December 2025 and again in February 2026 to support definition, clarity and understanding of process activities, roles, and responsibilities within the CNSC. This update included input and feedback from teams involved, including Regulatory Operations Branch (ROB), Corporate Services Branch (CSB) and Legal and Commission Affairs Branch (LCAB). There is also a complete assessment checklist in place to support with reviews against the criteria established in REGDOC-3.3.1.
The audit found that roles and responsibilities were duplicative and gaps in coordination and communication existed resulting in delays in receiving information guarantee assessments.
The audit found that even though there is a process for the technical review, process ownership and accountability, including end-to-end ownership of the financial guarantee process and accountability for the decisions, there are aspects not clearly documented and assigned.
Roles, Responsabilities and Accountabillities
The audit found that roles and responsibilities were at times duplicative and that gaps in coordination and communication existed resulting in delays in access to the right information to support the financial guarantee assessment process.
The roles and responsibilities related to financial guarantees within the CNSC play a crucial part in ensuring that financial commitments from licensees are adequately reviewed, accepted, and managed. The CNSC must ensure that financial guarantees, such as letters of credit and surety bonds, are appropriately structured and sufficient to cover potential liabilities related to decommissioning activities.
Given the complexity of nuclear activities, it is essential that these responsibilities are well defined, clearly communicated, and effectively implemented across multiple branches within the CNSC. In the past, oversight and administration of the financial guarantee requirement at the CNSC has involved multiple teams across the ROB, CSB, and LCAB. Within ROB, Directorate of Nuclear Cycle and Facilities Regulation (DNCFR) responsibilities are shared among licensing and compliance staff, technical advisors, designated officers, Directorate of Power Reactors Regulation (DPRR) licensing and compliance staff, Directorate of Nuclear Substance Regulation (DNSR) licensing and compliance staff, and the Operations Secretariat (OpsSec), which supports horizontal operational activities such as training and planning. The Major Projects and Strategic Support Division (MPSSD) (within DNCFR) provides a coordinating role as well as specialist expertise for the technical decommissioning expertise. CSB manages the financial aspects of the financial guarantee requirement, while LCAB provides Legal Services (LS) support and performs the Commission Registry function.
In December 2025, the DNCFR approved the work instruction, How to: Review and Track Decommissioning Plans and Financial Guarantees, to provide a more structured and comprehensive approach to financial guarantee management and improve consistency in the process. This work instruction was amended in February 2026 to remove the upfront review by legal on the validity and enforceability of the financial guarantees, which removes duplication of efforts. The legal review will be an element of the Commission Member and Designated Officer Document existing processes.
The work instruction outlines all roles and responsibilities as part of the financial guarantee process, clarifying it is the Commission or a Designated Officer responsibility to accept (or reject) the financial guarantees. The work instruction identifies the responsibilities of several divisions involved in the process and addresses some of the concerns raised during interviews with various stakeholders and in the previous guidance. The work instruction includes guidance for:
- Licensee project officers across several directorates, co-ordinating with licensees, co-ordinating input for decision makers, and monitoring annual and 5-year compliance activities
- Finance specialists responsible for assessing compliance of the financial guarantee instruments with the criteria in REGDOC-3.3.1
- Decommissioning subject matter experts (SMEs) within DNCFR are responsible for the technical assessment of the decommissioning plans and cost estimates and consolidating findings with the inputs from finance for reporting results
The updated document introduces a detailed roles and responsibilities table, linking specific tasks to the responsible functions and positions, and providing a more systematic and transparent approach to reviews and approvals to support decision-making. Despite these improvements related to task clarity, an enhancement to provide an accountability, responsibility, consultation and informing (RACI) chart would be beneficial for understanding ownership and support efficient decision-making. This is supported by comments in interviews, which included: the distinction between coordination, ownership, and accountability was not well understood or documented; there was uncertainty if there was an “end-to-end” position responsible or single ‘process owner’, the level and/or perceived level of understanding of roles and accountabilities varied across directorates. Based on the review of the updated work instruction some of these misconceptions are not clarified.
While the work instruction supports governance of the financial guarantee process, overall governance would benefit from the development of a document that clearly articulates broader-level accountabilities within the CNSC.
Comparative Analysis with Regulators: Insights on Roles, Responsibilities, and Accountability
- A central function exists, generally within to oversee financial guarantees; however, legal and finance expertise are relied upon.
- Financial guarantees are widely used to ensure decommissioning, abandonment, waste management, and long-term monitoring and restoration activities
- Primary responsibility consistently rests with licensees, with regulators serving in oversight and enforcement roles to ensure compliance.
Conclusion
While the roles and responsibilities related to financial guarantees within the CNSC have evolved and improved through updates and clarifications, there are still opportunities and a need to enhance governance and accountability. By improving transparency in recommendations and ensuring clarity of shared ownership of financial guarantee management, reduce the risk of confusion or operational gaps, and ensure that financial guarantees are managed effectively in alignment with its regulatory requirements.
Recommendation 1
It is recommended that OpsSec, with support from DNCFR and FAD, determine and clearly document in the CNSC’s integrated management system (Navigator) the overall process ownership and accountabilities regarding the administration of financial guarantees.
Management Action Plan
Management agrees.
OpsSec will prepare an analysis of options and a recommendation for the overall process ownership and accountabilities and incorporate any clarifications within the CNSC’s IMS (Navigator) documentation where relevant.
Targeted completion date: October 2026
Guidance and Understanding
The audit expected the CNSC to have well defined communication and coordination between key stakeholders in place to ensure that reviews of proposed or updated financial guarantees are performed without duplication of effort.
Key Findings
Recent refinements and improvements to oversight and reporting suggest an intent from management to improve monitoring and transparency in the financial guarantee process.
Interviews with staff involved in the financial guarantee process and testing revealed inconsistent application of and/or understanding of expectations. This indicates a need to build greater rigor into the review process and to convey the importance of Financial Guarantees as part of licensing and the potential risk exposure to the CNSC. Additionally, the limited use of standardized tools (e.g., instrument templates beyond letters of credit) reduces opportunities to streamline and standardize financial guarantee reviews. During the audit, the Work Instruction was updated, an initiative which has been a positive contribution to clarify guidance.
Clarity and Understanding of the Guidance
The audit revealed that there is a need for continuous oversight, periodic reviews, and training on the updated work instructions and governance structures. Additionally, it was found that there were unclear expectations surrounding depth and thoroughness of review. The regular review of the work instruction should involve all branches to ensure that the roles and responsibilities remain aligned with any updates to regulatory documents, such as REGDOC-3.3.1. This collaborative approach would also help prevent any gaps in the financial guarantee management process and ensure that all relevant parties are continuously engaged in maintaining the effectiveness of the financial guarantee framework and understand their and their colleague’s ownership of the varying elements in the process.
The documentation review, sample testing and interviews highlighted that there is a lack of formal processes and documentation for some directorates/functions to assist in carrying out their roles related to the financial guarantee process beyond the guidance provided in the work instruction.
For example, the processes for reviewing and validating complex financial guarantees such as surety bonds or letters of credit are not well defined, leading to inconsistencies in assessments or validation practices. LCAB has established a framework for assessing the enforceability and reliability of these instruments. It was observed in conducting the tests on sampled financial guarantees, not all requirements defined in the work instruction were consistently understood, resulting in some controls not being applied. It was also suggested that increased co-ordination across the task owners to close loops and share information would enhance the clarity on specific files. Some noted the communication between branches is often informal, particularly for new staff, and the transition to SharePoint has introduced further challenges in documentation and record storage. On a broader context it may be beneficial to meet annually with representation from the cross functional groups to share feedback and insights.
Comparative Analysis with Regulators: Insights on Guidance
- Some regulators allow multiple instruments (e.g., letters of credit, surety bonds, trusts).
- In some cases, the regulating organization prescribed the types of financial institutions that applicants could use.
- Leading practice favors standardized guarantees instruments and templates, as they promote consistency in interpretation and application across different license types.
Completeness of Information Management
The audit found that there are efforts underway to strengthen tracking and information practices to improve the reliability of financial guarantee records and monitoring information, using the new MS365 tools implemented recently in operations. However, information management practices are not yet consistently controlled (e.g., incomplete tracker, incorrect link, unclear SharePoint file structure, incorrect assessment and inconsistent naming conventions), creating a risk that financial guarantee approval decisions and subsequent monitoring rely on incomplete or unreliable information, as well as creates inefficiencies.
Significant progress was made over the summer and fall of 2025 to create a new financial guarantee tracker built using the MS365 tools. The tracker links to various data sources in SharePoint, as licensee sites were being established and project officers were adding relevant documents. This centralized approach is efficient, and the access to information should be shared with FAD and LS as a source of information and reinforces the need for accuracy and completeness of data. The independent validation of information, in particular when transitioning documents and implementing the new system with new metadata, will minimize inaccuracies. At the time of conducting the audit not all licensees’ information had been transitioned.
Further, the FAD and LS rely on ROB licensing staff for recordkeeping of complete financial guarantee records, which includes the original documents and amendments, as well as tracking of information. It was noted in conducting the testing of sampled instruments and in interviews that reliance was often on individual Project Officers for ongoing management of financial guarantee documentation. In the updated work instruction, the requirement for monitoring of and ensuring documents of business value are saved in the appropriate SharePoint site is a responsibility of the waste and decommissioning SMEs. As the CNSC implements this new information management system, clarity on the document requirements, file structure, naming conventions, and tagging should be detailed in the work instruction, given the number of staff involved in the process and the enhanced used of data. This will result in improved ease of access to records and analysis based on reliable information.
In conducting tests on a sample of financial guarantees, the audit found that some original financial guarantee instruments were not found in the CNSC’s records department. Although the work instruction does not explicitly require retention of original instruments, certain guarantees may require presentation of the original document to access funds, creating a potential risk if originals are unavailable. In addition, amendments to financial guarantees often modify amounts or applicant names, while the governing terms and conditions remain in the original instrument. If original documents are not securely maintained, the CNSC may face challenges in confirming enforceability or accessing funds when required.
The audit observed, in the documentation review, an improved reporting to the Commission by Registry in the Annual Designated Officer Program Update to the Commission Annual Report, providing increased context and information.
Comparative Analysis with Regulators: Insights on Information Management
- Organizations use a wide range of tools and management systems to support their processes.
- While some organizations rely on separate, disconnected systems, leading practice is to integrate data from all licensees into a unified platform.
- Best practices highlight the use of an integrated Customer Relationship Management (CRM) system to centralize and manage all licensee data effectively.
Conclusion
Audit work identified opportunities to strengthen the oversight of financial guarantees through more formalized processes, improved record keeping and coordination across functions. While work instructions provide baseline guidance, procedures for reviewing and validating complex financial instruments are not consistently defined or applied, resulting in variability in practices. Informal communication, documentation challenges following the transition to SharePoint, and inconsistent understanding of requirements (particularly for new staff) further limit effectiveness. The audit concluded that clearer documentation, improved coordination, and periodic cross-functional engagement would enhance consistency, clarity, and overall governance.
Additionally, the audit concluded that efforts to improve information management should continue to be undertaken by management to ensure that financial guarantee assessments and decisions are rooted in complete and accurate information. Further, the updated information, including the financial guarantee tracker, should be shared with FAD and LS to ensure that their assessments are based on current and relevant information.
Recommendation 2
It is recommended that OpsSec, with support from DNCFR, FAD and LS, coordinate a horizontal training for all impacted staff, to ensure clarity of their roles and responsibilities, awareness of risk and mitigation controls, and process flow and those of their colleagues.
Management Action Plan
Management agrees.
Ops Sec will design and implement formal training for CNSC’s financial guarantee program and offer this training on a recurring basis. The key milestones are:
Training Approach Defined – objectives, audience, approach, content scope.
Training Pilot – content development, validation, and adjustment (*dependent on Recommendation #1, 3, 5).
Training Delivery – implementation and evaluation.
Targeted completion date: March 2028
Recommendation 3
It is recommended that DNCFR, with support from DPRR and DNSR, clearly document and expand process monitoring and reporting requirements based on the details/elements noted throughout this report where a lack of guidance or opportunity to strengthen controls based on performance and best practices exists.
Management Action Plan
Management agrees.
DNCFR will analyze existing process monitoring and reporting requirements and implement recommended improvements to strengthen controls where relevant. MPSSD will conduct an analysis and submit an analysis report with recommendations for DNCFR, DPRR and DNSR DG endorsement. ROB (coordinated by MPSSD) will implement any necessary changes in relevant Navigator documentation
Targeted completion date: July 2027
Risk Management
The audit expected that processes are in place to ensure that the CNSC consistently applies a graded approach to financial guarantees, considering the licensee’s risk profile, facility lifecycle stage, activity type, and decommissioning complexity, as outlined in REGDOC-3.3.1. In addition, the audit expected monitoring processes are in place to detect changes to risk, including licensee financial distress, changes in activities, performance issues or non-compliance.
Key Findings
A risk-informed/graded approach is described in REGDOC-3.3.1 but is not fully embedded in the technical work instruction.
There has been limited integration and documentation of risk considerations within the standard review process (e.g., license type, legal enforceability risk by instrument type). There is an opportunity to strengthen the regulatory requirements to mitigate some risks.
Risk Management
The audit reviewed REGDOC-3.3.1, along with its related guidance documents such as REGDOC-3.5.3, Regulatory Fundamentals, to assess how effectively the CNSC uses a graded approach when assessing financial guarantees. The audit found that REGDOC-3.3.1 and its related documents provide a foundation for applying a graded approach, aligning with international standards, and embedding a risk-informed methodology into the licensing and regulatory processes.
REGDOC-3.3.1 describes the use of a graded approach in assessing financial guarantees, stating that the assessment must consider factors such as the facility lifecycle stage, the type and complexity of activities, and the detail provided in the decommissioning plan. These elements are key in determining the level of financial guarantee required, ensuring that the guarantee is proportional to the associated decommissioning risks. Moreover, this approach is further refined in REGDOC-3.5.3, which provides a more detailed framework for applying regulatory requirements in a manner that corresponds to the relative risks associated with nuclear facilities and licensed activities. By integrating risk-informed principles and considering facility-specific characteristics, the CNSC ensures that the regulatory oversight, including the assessment of financial guarantees, is proportionate to the risks involved. This is supported by technical assessments, performance history, and safety evaluations, and is consistent with international safety guidelines, such as those from the International Atomic Energy Association (IAEA Safety Glossary). The CNSC’s approach, therefore, demonstrates a structured and consistent framework for assessing financial guarantees and ensuring that these instruments are both adequate and enforceable.
Despite the clear framework outlined in REGDOC-3.5.3, the review of the work instruction used to assess financial guarantees revealed some gaps in how the graded approach is applied in practice. While the work instruction outlines procedures for reviewing decommissioning plans, cost estimates, and financial guarantees, it does not fully integrate all of elements of the graded approach. Specifically, while the work instruction incorporates technical assessments and administrative steps for reviewing documents, it lacks direct reference to evaluating facility complexity, potential harm, or the varying levels of oversight required based on the risk profile of the facility, activity or licensee. These omissions represent a missed opportunity to align the work instruction more closely with the full scope of the graded approach outlined in REGDOC-3.5.3 and in REGDOC-3.3.1. A clearer linkage between risk profiles and the depth of financial guarantee reviews would help ensure that the CNSC's oversight remains consistent with the risk-informed principles of the graded approach.
In interviews with operations, legal and finance, it became clear that while the CNSC has a process for assessing financial guarantees, there are perceived challenges in applying a consistent, risk-based approach across all licensees. Staff highlighted the following risk drivers associated with the assessment of decommissioning plans, cost estimates and financial guarantees:
- newer licensees or facilities transitioning between license categories
- private entities with their own guarantees in place
- standalone licensees vs facilities with government-backed guarantees
- integration of licensee performance history, such as incidents of non-compliance or with a record of enforcement actions
- legacy financial instruments, in particular that pre-date current regulatory criteria may no longer meet today's standards or where records are incomplete
- limited tracking of the historical decisions
- type of financial instrument
- lack of standardized form for financial instruments, such as surety bonds in REGDOC-3.3.1
- financial health of applicants and licensees
If financial guarantees are insufficient to cover the full costs of decommissioning, in addition to financial risk, the CNSC could face reputational risk, including intense media analysis, public criticism over regulatory oversight, and potential challenges questioning its ability to protect the public interest. It was noted that a review or summary of costs estimates across licensee types had not been performed which would provide specialists with a contextual reference to assess licensee submissions and indicate a potential risk of underestimating costs. In the document review the audit team noted one instance where a Designated Officer, level Director General, approved a 2-year license where the record of decision specified the financial guarantee was insufficient to fund a decommissioning of the site, without an estimate of the exposure to quantify the risk, which later materialized. The licensee had not provided a cost estimate of decommissioning and staff did not apply SMEs to quantify an estimated cost.
In the sample testing of financial guarantees, it was noted one financial guarantee instrument, a surety bond, was not issued by a Canadian institution, that can be an added element of risk. The REGDOC 3.3.1 states “Surety bonds should name the CNSC as a beneficiary and the insurance or bonding agents should be Canadian companies subject to Canadian regulatory oversight.” This is another instance where amending the word should to shall be considered and extended to the other types of instrument requirements detailed in section 4.3 of the REGDOC-3.3.1.
The Regulatory Affairs Branch (RAB) is responsible for coordinating updates to regulatory documents when needed, ensuring they remain current, aligned with the CNSC’s regulatory framework, and reflective of evolving requirements and policies. As a result, any amendments to regulatory documents or regulations are initiated by operations and are implemented by RAB to ensure that all amendments are properly coordinated and consistent with the CNSC’s overall regulatory framework.
Comparative Analysis Insights on Risk Management
- All organizations incorporate risk considerations into their financial guarantee frameworks, particularly during the licensing or approval stage. Leading practice includes the assessment of financial risk and viability of the applicant during this stage.
- Ongoing reassessment of enforceability and financial risk is not consistently documented throughout the lifecycle of guarantees.
- Leading practice includes conducting an annual review supported by detailed documentation. This typically involves analyzing financial statements, decommissioning plans, and other relevant materials to inform the risk assessment.
- Embedding financial expertise within the operations team is considered a strong practice, enabling deeper understanding of financial risks and their implications.
- While most organizations currently rely on estimated costs, there is active discussion about incorporating actual cost data whenever feasible to improve accuracy.
Conclusion
The regulatory framework supports a graded, risk-informed approach to financial guarantees. The audit found that the work instruction had limited consideration of the risk profile of the facility, activity or licensee. Strengthening operational guidance and licensee requirements, improving risk differentiation, and ensuring more rigorous review practices would enhance the reliability and defensibility of financial guarantee assessments.
Recommendation 4
It is recommended that DNCFR, with support from FAD, RAB and LS, complete a targeted analysis of REGDOC-3.3.1’s requirements and guidance, with the aim to strengthen requirements and clarity for licensees and proponents on meeting those requirements, and in doing so further reduce risks to the CNSC.
Management Action Plan
Management agrees.
DNCFR will coordinate a targeted analysis of REGDOC-3.3.1 and submit an analysis report with recommendations for Regulatory Framework Steering Committee member endorsement. Any additional follow-up will be addressed under RAB’s existing process for RegDoc review. CNSC's licensing divisions can communicate to licensees and proponents any updated expectations while this review is underway and until any outcomes are implemented.
Targeted completion date: March 2027
Recommendation 5
It is recommended that the DNCFR, with support from OpsSec and FAD, clarify the use of the graded approach as part of the financial guarantee process and consider whether further risk considerations should be integrated.
Management Action Plan
Management agrees.
DNCFR will analyze the use of the graded approach during the assessment of financial guarantees and implement recommended improvements, including the integration of additional risk considerations where relevant. MPSSD will conduct the analysis and submit an analysis report with recommendations for DNCFR DG endorsement. DNCFR (coordinated by MPSSD) will implement any necessary changes in relevant Navigator documentation.
Targeted completion date: March 2027
Compliance Mechanisms
The audit expected that processes and controls are established to ensure compliance with the CNSC’s acceptance criteria for financial guarantees, including liquidity, certainty of value, adequacy of value and continuity. It was also expected that monitoring processes are in place to detect changes to risk, including licensee financial distress, changes in activities, performance issues or non-compliance.
Key Findings
Past cases of non-compliance with REGDOC-3.3.1 have surfaced practical lessons learned about instrument terms and following established processes, as well as a greater understanding of risks.
Key controls and triggers are not operating as intended (e.g., The Regulatory Information Bank (RIB) information tracking system is not used to trigger five-year reviews and Annual Compliance Reviews (ACRs).
Controls and Monitoring
Recently, ROB conducted an internal review on a specific licensee (Case A) financial guarantee to identify gaps in the process and/or where processes were not followed and to identify lessons learned and corrective actions. This initiative demonstrates a willingness to evolve and strengthen the processes and provided valuable insights; however, the audit team would have expected to see a deeper root cause analysis to provide greater clarity into the underlying gaps in controls and monitoring. As an example, one corrective action and conclusion was “The publication of REGDOC-3.3.1 has addressed these issues by introducing measures such as automatic renewal, improved notification protocols, and clearer documentation requirements to prevent similar gaps in financial assurance do not occur in future financial guarantee instruments. This REG DOC was not in place when the FG was approved by the Commission in 2017. Like all other REGDOCs, it gets reviewed and updated on a periodic basis.” While the audit team agrees that the automatic renewal term, detailed in section 5.3 of REGDOC-3.3.1, is a strong control, it would be further enhanced if the guarantee had complied with section 5.4 of the REGDOC which requires the payout of the financial guarantee to the beneficiary upon expiry if the licensee fails to provide an acceptable replacement. As a result of the importance of these two elements to be understood in conjunction, particularly the payout clause, the testing of sample financial guarantees included a review of this element of control. Testing revealed one letter of credit, accepted by the CNSC, did not have the recommended payout clause. In follow-up with operational staff, the significance of the use of “should” in critical sections of the REGDOC was highlighted as a concern, particularly in circumstances which challenge the enforceability of this key provision, where “shall” would be considered an improvement. Interviews with Legal Services also emphasized the importance of the enforceability and continuity of financial guarantee instruments in the assessment process.
The CNSC has implemented mechanisms to track and monitor financial guarantees, including notification systems like RIB and the financial guarantee tracker. In Case A, it was highlighted that the required 5-year review was not conducted, and the corrective action included that “A formal work instruction has now been issued and implemented that outlines clear requirements for tracking reviews within the RIB tracking system to ensure that all future reviews are conducted on time and systematically recorded”. However, the audit found that the work instruction does not detail the use of RIB for 5-year reviews, and in testing the sample financial guarantees the audit revealed this was not an isolated incident and that these tools are not always used, further compromising the effectiveness of monitoring and oversight. Additionally, there was not a consistent understanding by staff the requirement for a 5-year review for all nuclear facilities or activities for Class IA and IB licences, further necessitating training to improve clarity and understanding as recommended in section 5.2.1.
Another recommended corrective action, which internal audit agreed with, was to clarify and strengthen guidance and expectations for staff in the work instruction and for licensees in the REGDOCs on the Annual Compliance Reviews (ACR). The testing of sample financial guarantees confirmed several incidents where the ACR trigger was not recorded in RIB and there remains a reliance on licensee-provided updates for financial guarantee validity. Without regular, independent verification and clear escalation procedures for overdue or missing confirmations, the CNSC may struggle to address issues in a timely manner. The assessment did not consider broader underlying potential causes, such as the risk factors surrounding the licensee which may have flagged the need for increased oversight.
In addition, the current ACR process places the reliance on licensee self-reporting for confirming the validity and sufficiency of financial guarantees presents a vulnerability. Without independent verification by CNSC staff, there is a significant risk of outdated or inaccurate information being accepted as valid, which undermines the reliability of the financial guarantee process. Interviews with Operations highlighted concerns about the impact of changing licence activity levels on cost estimates and whether financial guarantees were being assessed in isolation. Specifically, that cost estimates, which serve as the basis for financial guarantees, are often reviewed without considering the broader context of licensing, inspections, and operational scope. Operations noted that the verification of these estimates is insufficient, with third-party validation not being routinely applied as it should be. The lack of integration between cost estimates and operational realities represents an internal control gap, as financial guarantees may not adequately reflect the true costs of decommissioning.
While periodic reviews are required by the regulatory framework, delays or missed reviews may result in inadequate financial guarantees that are not aligned with updated decommissioning plans or cost estimates. The absence of periodic supervisory reviews further increases the risk of non-compliance, as there is no clear mechanism in place to assess whether staff are adhering to established procedures for financial guarantee oversight. The work instruction does not mandate periodic quality assurance reviews or management oversight to confirm that controls are operating as intended, creating a potential gap in the regulatory oversight process.
Comparative Analysis with Regulators: Insights on Controls and Monitoring
- Controls support the initial review and acceptance of financial guarantees.
- Ongoing monitoring is largely driven by periodic reviews and event-based triggers rather than a comprehensive, continuous control framework, which can leave emerging risks undetected between review cycles. Leading practice included automatic renewal (including 60 or 90 day notice of cancellation) and automatic payout clauses to mitigate risks.
- Guarantees are reassessed at key regulatory touchpoints, including licensing, renewals, amendments, and inspections.
- All organizations maintain a mandatory review cycle, though the level of system sophistication varies—some use integrated, systematic processes while others rely on more manual approaches.
- Leading practice includes an annual update requiring licensees to submit specific documentation, followed by internal analysis to identify changes in risk indicators related to both operational and financial capability of the licensee.
Conclusion
The audit revealed that REGDOC-3.3.1 is a solid regulatory framework for financial guarantees; however, gaps were identified in its application and enforcement. Key issues include the use of non-mandatory language, reliance on licensee self-reporting, and inconsistent use of tracking tools, which pose risks to the effectiveness of monitoring and oversight. The audit also highlights the need for improved accountability, independent verification, and enhanced supervisory reviews to ensure compliance with financial guarantee requirements.
Recommendation #2 on horizontal training, recommendation #3 on improving technical work instructions and recommendation #4 on strengthening the regulatory requirements identified earlier in the report will also address the controls and monitoring opportunities of improvements.
Financial Guarantee Program
The audit sample was expanded to include one licensee under the insurance-based Financial Guarantee Program, based on the risk informed section criteria. The audit expected to quantify the level of exposure and to assess the adequacy of regulatory framework and processes to respond to identified risks.
Key Findings
The insurance-based Financial Guarantee Program has provided effective coverage for most licensees that have participated. Over time, growth in some licensees’ activities and/or decommissioning cost estimates has increased the need for stronger monitoring controls and assessing whether alternate financial guarantees are required.
Financial Guarantee Program
The insurance-based Financial Guarantee Program was introduced in 2000 to provide financial guarantees for the termination of licensed activities, such as for nuclear substances and radiation devices, prescribed equipment, and Class II facilities. Under the insurance-based program, the CNSC is the insured party and the beneficiary. Since introduction there has been a $1 million cap of insurance coverage per licensee. Based on the 2026-27 financial program data there is currently a difference between the amount insured and the estimate of decommissioning costs of $18.7 million, with the majority related to one licensee, that was included in the sample of financial guarantees for testing:
| ($ thousands) | Estimated Decommissioning Costs | Financial Coverage from the Insurance Program | Gap in Financial Guarantee |
|---|---|---|---|
| One nuclear substances and radiation devices, prescribed equipment licensee | 12,405 | 1,000 | 11,405 |
| Balance of nuclear substances and radiation devices, prescribed equipment licensee | 74,072 | 68,798 | 5,724 |
| Class II facilities | 5,623 | 3,623 | 2,000 |
| Total | 92,100 | 73,421 | 18,679 |
There is a mechanism in Section 18 the current REGDOC-3.3.1, highlighting the program is flexible when a licensee’s activities do not meet the prescribed formula in the Financial Insurance Program. In such situation, the licensee has the option to propose another form of financial guarantee for review and acceptance by the Commission. The proposed financial guarantee would have to comply with criteria in section 3 of REGDOC-3.3.1 (liquidity, certainty of value, adequacy of value and continuity) and section 4 (acceptable instrument for a financial guarantee). This alternative is also explained on the CNSC website under the Q&A where the program is explained. Finance has not informed operations of the gap in financial guarantees and the CNSC has not required licensees to provide additional financial guarantees where this risk exists.
Further, the 2026-27 presents a vulnerability, especially given rising decommissioning costs. FAD, in collaboration with DNSR, revised many of the decommissioning costs for the 2026-2027 insurance program calculations, which it had the authority to do up to a value of $1 million. For those more complex cost estimates, Finance has engaged with Operations to evaluate the remaining decommissioning cost estimates to undertake corrective and mitigating action to address ensure the adequacy of financial guarantee coverage in the future. These updates will increase the current gap in financial guarantee coverage. These updated cost estimates will be considered in the upcoming renewal of the insurance policy in 2026-27, which presents an opportunity to reassess the adequacy of current coverage mechanisms.
Conclusion
The audit identified an $18 million gap in coverage under the Financial Guarantee Program for nuclear substances and radiation devices, prescribed equipment, and Class II facilities. FAD has identified the growing financial exposure due to rising decommissioning costs, particularly with the current $1 million cap per licensee, and has initiated action to review those decommissioning costs where there is remaining uncertainty. The option to require licensees not adequately covered by the Financial Guarantee Program to have incremental alternative coverage should be considered by the licensing officers.
Recommendation 6
It is recommended that the DNSR, with support from FAD, establish a process to monitor the sufficiency of the coverage, and to outline the necessary steps to address any gaps in financial guarantee coverage for nuclear substances and radiation devices, prescribed equipment, and Class II facilities.
Management Action Plan
Management agrees.
6a. DNSR and FAD will work together to determine and document a structured monitoring process that includes annual reviews of the financial guarantee coverage for nuclear substances and radiation devices, prescribed equipment, and Class II facilities. The process will clearly assign responsibilities, define evaluation criteria, and establish documentation requirements.
6b. In addition, DNSR will address the current gaps in financial guarantees, including taking corrective actions such as adjusting guarantee amounts through increased insurance coverage and using a different financial guarantee instrument for licensees exceeding the coverage offered by the insurance, consistent with REGDOC 3.3.1. This will align with the timing of the next period of coverage under the Financial Guarantee Program.
Targeted completion date: March 2027
Overall Conclusion
Overall, the CNSC has established a regulatory framework for financial guarantees; however, the audit found that while roles and responsibilities have evolved, additional clarity, accountability, and improved record keeping would support more consistent and risk-informed decision-making. These improvements include enhanced guidance, training and stronger regulatory requirements.
In some instances, documentation, accuracy of work, and adherence to processes may contribute to differences in oversight. These factors increase the likelihood that financial guarantees may not fully reflect current decommissioning costs or provide adequate protection in the event of licensee default. The audit also noted a coverage gap under the insurance-based Financial Guarantee Program and which contribute to increased financial exposure. Strengthening verification processes, enhancing monitoring activities, and improving information management would help ensure that financial guarantee assessments and records remain accurate, complete, and timely.
In summary, the CNSC has a foundation in place, and continued enhancements in governance, documentation, coordination, and monitoring would further support the effectiveness of the financial guarantees. These improvements would help ensure that financial guarantees are consistently assessed, appropriately risk-informed, and sufficient to support safe and effective decommissioning across regulated facilities.
Appendices
"Appendix A: Recommendations and Management Action Plans"
| Recommendation | Management Action Plan | Targeted completion date |
|---|---|---|
|
Management agrees.
OpsSec will prepare an analysis of options and a recommendation for the overall process ownership and accountabilities and incorporate any clarifications within the CNSC’s IMS (Navigator) documentation where relevant. |
October 2026 |
|
Management agrees.
Ops Sec will design and implement formal training for CNSC’s financial guarantee program and offer this training on a recurring basis. The key milestones are:
|
March 2028 |
|
Management agrees.
DNCFR will analyze existing process monitoring and reporting requirements and implement recommended improvements to strengthen controls where relevant. MPSSD (within DNCFR) will conduct an analysis and submit an analysis report with recommendations for DNCFR, DPRR and DNSR DG endorsement. ROB (coordinated by MPSSD) will implement any necessary changes in relevant Navigator documentation. |
July 2027 |
|
Management agrees.
DNCFR will coordinate a targeted analysis of REGDOC-3.3.1 and submit an analysis report with recommendations for Regulatory Framework Steering Committee member endorsement. Any additional follow-up will be addressed under RAB’s existing process for RegDoc review. CNSC's licensing divisions can communicate to licensees and proponent any updated expectations while this review is underway and until any outcomes are implemented. |
March 2027 |
|
Management agrees.
DNCFR will analyze the use of the graded approach during the assessment of financial guarantees and implement recommended improvements, including the integration of additional risk considerations where relevant. MPSSD will conduct the analysis and submit an analysis report with recommendations for DNCFR DG endorsement. DNCFR (coordinated by MPSSD) will implement any necessary changes in relevant Navigator documentation. |
March 2027 |
|
Management agrees. 6a. DNSR and FAD will work together to determine and document a structured monitoring process that includes annual reviews of the financial guarantee coverage for nuclear substances and radiation devices, prescribed equipment, and Class II facilities. The process will clearly assign responsibilities, define evaluation criteria, and establish documentation requirements. 6b. In addition, DNSR will address the current gaps in financial guarantees, including taking corrective actions such as adjusting guarantee amounts through increased insurance coverage and using a different financial guarantee instrument for licensees exceeding the coverage offered by the insurance, consistent with REGDOC 3.3.1. This will align with the timing of the next period of coverage under the Financial Guarantee Program. |
December 2026
March 2027 |
Appendix B: Audit Criteria
| Line of Inquiry 1: Governance |
|
1.1 Key CNSC staff responsibilities and accountabilities in relation to financial guarantees are clearly defined, communicated understood, and implemented.
1.2 Communication and coordination between key stakeholders are in place to ensure that reviews of proposed or updated financial guarantees are performed without duplication of effort. |
| Line of Inquiry 2: Risk Management |
|
2.1 Processes are in place to ensure that the CNSC consistently applies a graded approach to financial guarantees, considering the licensee’s risk profile, facility lifecycle stage, activity type, and decommissioning complexity, as outlined in REGDOC-3.3.1.
2.2 Monitoring processes are in place to detect changes to risk, including licensee financial distress, changes in activities, performance issues, or non-compliance |
| Line of Inquiry 3: Internal Controls |
|
3.1 Processes are in place to ensure credible cost estimates for decommissioning plans, which form the basis of the Financial Guarantee.
3.2 Processes and controls are established to ensure compliance with the CNSC’s acceptance criteria for financial guarantees, including liquidity, certainty of value, adequacy of value and continuity. |
Appendix C: 2018 vs. 2026 Audit of Financial Guarantees – Findings and Recommendations
| Audit Theme/Scope/Criteria | 2018 Audit Findings | 2026 Audit Findings | Level of Alignment | Interpretation |
|---|---|---|---|---|
| Overall Control Environment | Financial guarantee values adequate and instruments continuous (not expired). | Regulatory framework and processes established; improvements underway (SharePoint tracking, updated work instructions, cost updates). One instrument in sample found not to pay out on expiry or if replacement not satisfactory. | Improvement | Control framework strengthened since 2018; foundational issues partially addressed. |
| Internal Controls — System of Record / Tracking | No consolidated detailed system of record for tracking financial guarantees. | Tracking tool recently developed but controls and monitoring not always applied consistently. | Partial repeat (control effectiveness issue) | System exists now, but effectiveness and consistent use remain concerns. |
| Internal Controls — Receipt of Instruments | No adequate control for receipt of original instruments. | Not explicitly identified as a gap. | n/a | n/a |
| Internal Controls — Validation of Instruments | No adequate control for validation against Commission decisions. | Not explicitly identified as a gap. | n/a | n/a |
| Internal Controls — Recording Instrument Details | Weak recording of instrument details (amounts, terms, expiry, obligations). | Tracking tools and monitoring exist but inconsistently applied. | Partial overlap | Recording implemented but monitoring and oversight remains an issue. |
| Internal Controls — Storage and Safekeeping | No adequate safeguards for original instruments. | Completeness of financial guarantee instruments (consolidated original and amendments), ease of locating, non-specific instructions on e-filing and no instructions on paper records | Partial overlap | Clarity in work instructions required |
| Roles and Responsibilities / Governance | Roles and responsibilities for monitoring not clearly defined. | Roles documented but not clearly understood; unclear end-to-end accountability. | Duplication | Governance clarity remains an ongoing weakness from 2018 to 2026. |
| Monitoring Processes | No clear monitoring processes, procedures, or responsibilities. | Monitoring mechanisms exist but not consistently applied; risk of delayed identification of issues. | Duplication | Monitoring introduced but effectiveness and consistency and clarity. |
| Ongoing Validity Monitoring | CNSC may not consistently monitor ongoing validity of financial guarantees. | Monitoring and periodic review not always applied as intended. | Duplication | Same risk persists and monitoring effectiveness gap. |
| Risk Management / Risk-Informed Approach | Not a major focus of findings. | Risk-informed oversight not consistently applied; risk considerations not fully integrated. | New | 2026 audit expects higher risk management maturity than 2018. |
| Guidance and Training | Not specifically identified. | Guidance and training not consistently embedded across functions. | New | Organizational knowledge, capability and consistency now a concern. When people know what to do and understand their contribution improves compliance rates are higher. |
| Regulatory Framework / Guidance | Not specifically identified. | Some risks could be mitigated with updates to regulatory documents. | New | Strengthen regulatory clarity. |
| Financial Guarantee Coverage Sufficiency | Not specifically identified. | Insurance-based program shows coverage gaps in some cases. | New | Financial exposure risk emerging; not previously identified. |
| 2026 Recommendation | Related 2018 Recommendation | Level of Duplication | Implementation Implication |
|---|---|---|---|
| 1. Document process ownership and accountabilities in the integrated management system. | 2018 Rec 2; define internal controls, roles and responsibilities, and system of record. | Partial overlap | Similar governance issue (roles and accountability clarity). 2026 suggests roles/process ownership still not sufficiently documented; likely incomplete implementation of 2018 Rec 2. |
| 2. Coordinate horizontal training for staff on roles, responsibilities, risks, and process flow. | 2018 Rec 2; define roles/responsibilities and internal controls. | Partial overlap | 2018 focused on defining roles; 2026 adds training and awareness. Indicates implementation focused on documentation, but not organizational understanding; control maturity gap remained. |
| 3. Expand process monitoring and reporting requirements and strengthen guidance. | 2018 Rec 3; implement processes and systems for monitoring compliance, reporting obligations, and validity of financial guarantees. | Strong overlap / near duplication | Both address monitoring and reporting processes. Reappearance in 2026 suggests 2018 monitoring framework not fully effective or comprehensive. |
| 4. Targeted analysis of REGDOC-3.3.1 requirements to strengthen clarity and reduce risk. | No direct equivalent (2018 focused on process controls, inventory, storage, monitoring). | New recommendation | New regulatory guidance focus; not a repeat. |
| 5. Clarify graded approach and integrate additional risk considerations. | No direct equivalent. | New recommendation | Introduces risk-based approach not previously addressed. |
| 6. Establish process to monitor sufficiency of financial guarantee coverage and address gaps. | 2018 Rec 3; periodic monitoring of validity and compliance reporting. | Partial overlap (expanded scope) | 2026 moves beyond validity monitoring to coverage sufficiency and gap remediation; indicates 2018 monitoring did not fully address risk exposure. |
Appendix D: Acronyms
| Acronym | Definition |
|---|---|
| ACR | Annual Compliance Review |
| CNSC | Canadian Nuclear Safety Commission |
| CRM | Customer Relationship Management |
| CSB | Corporate Services Branch |
| DNCFR | Directorate of Nuclear Cycle and Facilities Regulation |
| DNSR | Directorate of Nuclear Substance Regulation |
| DPRR | Directorate of Power Reactors Regulation |
| FAD | Financial Administration Directorate |
| IAEA | International Atomic Energy Agency |
| IMS | Integrated Management System |
| LCAB | Legal and Commission Affairs Branch |
| LS | Legal Services |
| MPSSD | Major Projects and Strategic Support Division |
| MS 365 | Microsoft 365 |
| NSCA | Nuclear Safety and Control Act |
| OpsSec | Operations Secretariat |
| RAB | Regulatory Affairs Branch |
| RACI | Responsibility, Accountability, Consulted, Informed |
| REGDOC | Regulatory Document |
| REGDOC-3.3.1 | Financial Guarantees for Decommissioning of Nuclear Facilities and Termination of Licensed Activities |
| REGDOC-3.5.3 | Guidance on graded approach |
| RIB | Regulatory Information Bank |
| ROB | Regulatory Operations Branch |
Page details
- Date modified: